CVE-2024-41829

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

History

14 Aug 2024, 19:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 7.5
References () https://www.jetbrains.com/privacy-security/issues-fixed/ - () https://www.jetbrains.com/privacy-security/issues-fixed/ - Vendor Advisory
CWE CWE-287
First Time Jetbrains
Jetbrains teamcity
CPE cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) En JetBrains TeamCity antes de 2024.07, se podía robar un código OAuth para JetBrains Space a través de la conexión de Space Application.

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-08-14 19:04


NVD link : CVE-2024-41829

Mitre link : CVE-2024-41829

CVE.ORG link : CVE-2024-41829


JSON object : View

Products Affected

jetbrains

  • teamcity
CWE
CWE-287

Improper Authentication

CWE-303

Incorrect Implementation of Authentication Algorithm